Show filters
93 Total Results
Displaying 1-10 of 93
Sort by:
Attacker Value
Unknown
CVE-2013-3323
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
0
Attacker Value
Unknown
CVE-2015-5016
Disclosure Date: March 27, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
0
Attacker Value
Unknown
CVE-2017-1208
Disclosure Date: July 05, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778.
0
Attacker Value
Unknown
CVE-2017-1176
Disclosure Date: July 05, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.
0
Attacker Value
Unknown
CVE-2017-1175
Disclosure Date: July 05, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.
0
Attacker Value
Unknown
CVE-2016-8987
Disclosure Date: June 08, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.
0
Attacker Value
Unknown
CVE-2016-9977
Disclosure Date: June 07, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.
0
Attacker Value
Unknown
CVE-2016-9976
Disclosure Date: May 03, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 120252.
0
Attacker Value
Unknown
CVE-2016-8924
Disclosure Date: April 26, 2017 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.
0
Attacker Value
Unknown
CVE-2015-0107
Disclosure Date: April 24, 2017 (last updated November 26, 2024)
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.
0